logo

Database

Insecure file upload In codeigniter4/framework

Description

CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules

Impact

This is an unsafe file upload validation vulnerability that can lead to remote code execution in vulnerable application configurations.

Applications are impacted when they:

    validate uploads using is_image or mime_in without an independent safe extension check, such as ext_in on patched versions

    save uploaded files using the client-supplied filename

    place uploads in a web-accessible directory where PHP files can execute

Patches

Upgrade to v4.7.4 or later.

Workarounds

    Save uploads outside the public web root, preferably under writable/uploads.

    Use $file->store() or $file->move($path, $file->getRandomName()) instead of preserving the original client filename.

    Disable script execution in any public upload directory.

    Manually verify the client filename extension before moving the file.

    For image uploads, reject files when $file->getClientExtension() is not an allowed image extension.

    For exact MIME-type validation, reject files when $file->getClientExtension() does not match $file->guessExtension().

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions